Remote Access Tool Detection in Secure Transactions via Network Perturbation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively detect fraudulent transactions carried out using remote access tools, which can impersonate authorized users and compromise secure operations.

Innovation Solution

A method and system that actively perturb network conditions during transactions to collect and compare user interaction data, identifying deviations indicative of remote access tool usage by analyzing timing distributions and interaction patterns, and terminating suspicious transactions if a predefined threshold is exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then user convenience is maintained, but security against remote access fraud is insufficient

Engineering Contradiction:
Improvetransaction securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by actively perturbing the network connection before the fraudulent transaction can complete. Network perturbations are injected during the transaction process to proactively test for remote access tool usage, allowing detection before significant damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary detection mechanism that sits between the user's device and the network. This intermediary monitors user interactions and network traffic, analyzing timing distributions and interaction patterns to detect remote access tool usage without directly interfering with the legitimate transaction flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network perturbation is applied to detect remote access tools, then detection accuracy improves, but transaction processing time increases

Engineering Contradiction:
Improveremote access tool detection accuracyVSAvoidtransaction processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies periodic network perturbations rather than continuous disruption. Network perturbations are injected at specific intervals during the transaction, and user interaction timing is analyzed during these perturbation periods. This periodic approach maintains detection accuracy while minimizing impact on overall transaction processing time.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system uses partial action by applying network perturbations only to specific network connections suspected of using remote access tools, rather than disrupting all transactions. The perturbation intensity and duration are carefully controlled to achieve sufficient detection accuracy without excessively prolonging transaction processing.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If user interaction data is collected and analyzed in real-time, then fraud detection capability improves, but system resource consumption increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the critical features needed for fraud detection from user interaction data, rather than analyzing all possible data points. Specifically, it focuses on timing distributions of user interactions and network perturbation responses, extracting these key features for analysis while ignoring redundant information, thereby reducing computational resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system replaces complex mechanical analysis methods with more efficient computational approaches. Instead of using resource-intensive machine learning models, it employs statistical analysis of timing distributions and interaction patterns, which requires significantly fewer computational resources while maintaining effective fraud detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250328895A1Detection of use of a remote access tool for secure transactions
Publication Date: 2025.10.23 LEXISNEXIS RISK SOLUTIONS FL INC
  • US20250328895A1 patent drawing
  • US20250328895A1 patent drawing
  • US20250328895A1 patent drawing

AI summary

A method for determining whether a secure transaction between a user computing device and a server, connected via a network, is controlled remotely via a remote access tool. The method includes, during the secure transaction, actively perturbing and/or probing the network to change the conditions in the network. During perturbing of the network, data relating to user interactions with a user interface associated with the user computing device is collected and compared to reference data relating to user interactions carried out prior to the secure transaction or prior to perturbing of the network. Based on the comparison, a probability that the secure transaction is carried out via a remote access tool is computed and is compared to a predefined threshold. If the threshold is exceeded, the secure transaction is terminated.